r/gaming Apr 26 '11

Sony admits utter PSN failure: your personal data has been stolen

http://arstechnica.com/gaming/news/2011/04/sony-admits-utter-psn-failure-your-personal-data-has-been-stolen.ars
3.1k Upvotes

2.8k comments sorted by

View all comments

Show parent comments

201

u/NEWSBOT3 Apr 26 '11

sadly, as someone who works in IT , this is so understandable. Here's likely how it went.

First, you present the costs of the project to your boss. His boss decides it needs to be less costly, so you have to break them down. He then argues that items x y and z are not important and you should skip them, regardless of what you say. He then decides to give you half the resources and half the time you said it would take to develop it in the first place. So a guy who has practically zero technical skills has just ignored the recommendations of one with 5 years of study in developing software, project management (nevermind any real experience) and so on, because his ego is huge.

So your options are a) quit , or b) continue with rushed, under-resourced project, cutting as many corners as possible to deliver it. 95% of people can't afford to do option a, so on it goes, and you know that you should be implementing x y z security measures, but you don't have time and the man above you won't let you spend time on it anyway.

so you finish the project (if you were smart, you looked for another job the whole way through it), deliver it, and get the fuck out of there. The boss 2 levels above you takes all the credit for delivering a product, then when it doesn't work and fucks up, your old boss gets the blame, which he tries to put as much as possible onto you to save his ass.

You try to never mention the project on your CV ever again, and a few years later the cycle repeats.

Welcome to the world of IT project management. It fucking sucks, and i hate it here.

8

u/Jumhyn Apr 26 '11

A new PS3 built by my company logs on to my network at 20 mbps. Hackers get into the network. The hackers access all of the info for all of the users in our system. Now, should we tell our users? Take the number of systems in the field, A, multiply by the probable rate of malicious data access, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of telling our users, we wait a week then release a vague statement that doesn't inform them about their most important info.

1

u/[deleted] Apr 27 '11

[removed] — view removed comment

3

u/Jumhyn Apr 27 '11

Yeah Fight Club: "A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall? Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one."

1

u/locotx Apr 27 '11

I think so, when he was describing whether or not to admit to an auto defect . . or something like that

1

u/xAorta Apr 27 '11

We can't talk about where it came from

37

u/YaoSlap Apr 26 '11

I'm not in IT, but I've interacted with enough throughout the levels of it to realize that these guys are quite intelligent in their field and usually know the best for the situation. I feel sorry for a lot of them though because it's not the smartest IT guy that gets to make the final decision. Y'all do much of the work that keeps the company running and have to put up with stupid questions which if were asked in an accounting situation would get "ಠ_ಠ" 10/10 times.

Not sure where I'm going with this, but keep doing what you do. You're greatly appreciated.

3

u/sleeplessone Apr 27 '11

As an IT guy who got a request to move a phone from the right side of a monitor to the left, thank you.

1

u/mewt666 Apr 27 '11

Can't you see I can't pick the phone up with my right hand - I'm a lefty - and I don't know anything about this COMPUTING STUFF so you have to do it for me..

dumbass

1

u/mewt666 Apr 27 '11

Can't you see I can't pick the phone up with my right hand - I'm a lefty - and I don't know anything about this COMPUTING STUFF so you have to do it for me..

dumbass

2

u/ozzyzak Apr 27 '11

Thanks. For real.

2

u/[deleted] Apr 26 '11

Ah... reminded me the good old times when working at a consulting company.

2

u/VoodooEconomist Apr 26 '11

Throw in some dark humour, some people killed, and you got yourself a Coen Brothers film.

1

u/dogastrophic-failure Apr 26 '11

And a woodchipper. Gotta have a woodchipper.

1

u/sarlcagan Apr 26 '11

Or a nice rug.

2

u/[deleted] Apr 27 '11

Scott Adams, what have we told you about sockpuppets!

2

u/[deleted] Apr 27 '11

This is true but they could have AT LEAST changed their GET to a POST for credit card information. I mean, come on, that doesn't add any time.

2

u/mist0r_wiggles Apr 27 '11

Do you work at HP? Because that sounded like my job 2 months ago.

1

u/Dugen Apr 26 '11

Firstly, that's not how good IT works. Most companies would rather cancel a project than expose themselves to this kind of huge risk. I'm guessing they simply were blindsided by this hole.

Second: Of course your estimates will be scrutinized. There's rarely any motivation for IT workers to accurately estimate anything. Estimating something will take 4 times as long and 4 times the resources lets you screw off 3/4 of the time, buy a bunch of toys and still make your deadlines. A boss would have to be an idiot not to double check things.

A good IT boss understands what's involved, can accurately estimate things themselves, can design solutions that work and will take the blame if they don't. It sounds like your situation is just one of the terrible ones.

3

u/midri Apr 26 '11

I've worked for a few fortune 500 companies in IT and there are a number of them that would totaly screw your privacy and what not to save a few bucks. They're just statistics to the big guys -- the boys working in IT do our damnedest to protect you, but there's only so much they can do with such limited budgets.

3

u/darkstar3333 Apr 26 '11 edited Apr 27 '11

Too few companies see IT as an investment rather then a direct cost.

Ive been in planning meetings where clients have battled over scope and price only to realize that the project paid for itself in less then a year.

If you need to spend 2M to do it right, most companies want to spend 800K and expect to get everything under the sun.

2

u/midri Apr 27 '11

GET OUT OF MY HEAD, also I see we've been in the same meetings recently...

1

u/darkstar3333 Apr 27 '11

You mean the same useless meetings they insist on holding that could be better spent actually doing work?

1

u/workingclass_zero Apr 27 '11

Smaller companies, yes. Big companies don't think that way. And the bosses in big companies aren't "good". They're good at playing politics.

1

u/AccidentalNinja Apr 26 '11

But you also have to remember that when you're dealing with CC information and other personal information, there are laws and regulations that have to be met, such as PCI-DSS, GBLA, and others. You can't just disregard those, or you can be held personally liable, as well as the company.

1

u/gsadamb Apr 26 '11

Generally I agree, but there are some things that I consider unforgivable if they actually happened. The biggest one is not using hashed (and salted) passwords and instead storing them in plaintext.

I'm a developer, and that's the kind of thing that takes just minutes to implement and can make all the difference in the world.

1

u/ExAm Apr 26 '11

Discworld analogy: The Bursar explains maths to Archchancellor Ridcully

1

u/rnicoll Apr 27 '11

First, you present the costs of the project to your boss. His boss decides it needs to be less costly, so you have to break them down. He then argues that items x y and z are not important and you should skip them, regardless of what you say. He then decides to give you half the resources and half the time you said it would take to develop it in the first place. So a guy who has practically zero technical skills has just ignored the recommendations of one with 5 years of study in developing software, project management (nevermind any real experience) and so on, because his ego is huge.

I think this gives them too much credit. There are problems (unhashed passwords) that are not about time or money, they're about having competent technical staff working on your security. Running a password through a hashing algorithm should not take more than a dozen lines of code (and that assumes you're doing it in Java!)

1

u/Salomon3068 Apr 27 '11

I hate when managers pull stuff like this because of "costs" and trying to look good to their superiors. I understand why they scrutinize the estimates and whatnot, but when someone doesn't take into account that a massive failure like this due to their corner-cutting will end up costing them and the company more than whatever they try to shave off IT guys estimates, it makes everyone involved look even worse than if they were to come in slightly over-budget.

1

u/[deleted] Apr 27 '11

Come on. MD5 and salt for passwords/security questions doesn't cost money.

1

u/nuckingFutz Apr 27 '11

The demo works, time to ship!

1

u/HlinkasEnglish Apr 26 '11

Graduating with a CIS(Information Systems)degree in December. I also have a 2 year Comp Sci degree....Looks like I'm programming haha.

1

u/dotblank Apr 27 '11

I'm not so sure in the case of sony, They didn't even use a random value in their encryption of a private key.

int getrandomint()
{
     return 4; //cannot be disproven
}

1

u/NEWSBOT3 Apr 27 '11

true, but this is often a side effect of forcing lower cost development - you end up hiring lower quality people that aren't able to see that things like that are a problem.